Virus

Résolu
Bonjour,

Depuis 2 jours j'ai mon bureau avec comme fond d'écran un message d'alerte :

win32/Adware.Virtumonde
win32/PrivacyRemover.M64

J'ai avast et spybot sur mon PC.
Je suis un grand novicede l'info !!

Quelqu'un pourrait-il m'aiderà m'en débarasser ?

MErci d'avance
Configuration: Windows Vista
Firefox 2.0.0.16

20 réponses

  1. super, merci encore et bonne soirée.
    0
    1. Contributeur sécurité
      Garde-le, un scan de temps en temps, en préventif est une très bonne chose.
      0
      1. Il me reste Malwarebytes' Anti-Malware sur le bureau.
        0
        1. Je vais suivre tes conseils et installer antivir.
          Par contre je pense qu'il y a une procédure pour supprimer proprement avast non ?

          Voilà le rapport :

          [ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

          -->- Recherche:

          C:\SmitFraudFix.exe: trouvé !
          C:\SmitFraudfix: trouvé !
          C:\Users\Fabrizio\Desktop\HijackThis.exe: trouvé !
          C:\Users\Fabrizio\Desktop\SmitFraudFix.exe: trouvé !
          C:\Users\Fabrizio\Desktop\hijackthis.log: trouvé !
          C:\Users\Fabrizio\Desktop\SmitFraudfix: trouvé !

          ---------------------------------
          -->- Suppression:

          C:\SmitFraudFix.exe: supprimé !
          C:\Users\Fabrizio\Desktop\HijackThis.exe: supprimé !
          C:\Users\Fabrizio\Desktop\SmitFraudFix.exe: supprimé !
          C:\Users\Fabrizio\Desktop\hijackthis.log: supprimé !
          C:\SmitFraudfix: supprimé !
          C:\Users\Fabrizio\Desktop\SmitFraudfix: supprimé !

          Fichiers temporaires nettoyés !
          Corbeille vidée!
          0
          1. Contributeur sécurité
            Parmi les antivirus gratuits, Antivir est recommandé par beaucoup :

            http://www.commentcamarche.net/telecharger/telecharger 55 antivir personal

            Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

            Télécharge toolscleaner sur ton Bureau :
            http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
            * Double-clique sur ToolsCleaner2.exe et laisse le travailler
            * Clique sur Recherche et laisse le scan se terminer.
            * Clique sur Suppression pour finaliser.
            * Tu peux, si tu le souhaites, te servir des Options facultatives.
            * Clique sur Quitter, pour que le rapport puisse se créer.
            * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
            0
            1. Et bien pour commencer le fond d'écran d'alerte a disparu.
              J'ai refait un test d'arrêt/redémarrage, et pas de problème.
              Je ne suis plus attaqué, plus d'alarme AVAST.
              Je pense que c'est tout bon.

              Si c'est le cas, un grand merci.
              Une dernière question, dois-je supprimer tout ce que j'ai installer pour la manip ? si oui, de quelle façon.
              Que me conseilles tu comme protection (avast suffit ?)
              0
              1. Contributeur sécurité
                As-tu encore des problèmes ?
                Comment se comporte le PC ?
                0
                1. Voilà

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 17:34:47, on 21/09/2008
                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                  C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                  C:\Program Files\Picasa2\PicasaMediaDetector.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                  C:\Program Files\itune\iTunesHelper.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Windows\ehome\ehtray.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Neuf\Media Center\MediaCenter.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Windows\ehome\ehmsas.exe
                  C:\Program Files\Windows Sidebar\sidebar.exe
                  C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                  C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Users\Fabrizio\Desktop\HiJackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                  O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                  O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                  O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\itune\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\Neuf\Media Center\MediaCenter.exe"
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                  O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                  O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                  O13 - Gopher Prefix:
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                  O23 - Service: FreezeScreenSaver - Unknown owner - C:\Windows\system32\FreezeScreenSaver.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                  O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                  0
                  1. Contributeur sécurité
                    C'est bien, ça se nettoie
                    Tu peux refaire un Hijackthis stp.
                    0
                    1. Hello, de nouveau moi.

                      voilà le rapport.

                      Malwarebytes' Anti-Malware 1.28
                      Version de la base de données: 1184
                      Windows 6.0.6001 Service Pack 1

                      21/09/2008 17:19:31
                      mbam-log-2008-09-21 (17-19-31).txt

                      Type de recherche: Examen complet (C:\|D:\|)
                      Eléments examinés: 191334
                      Temps écoulé: 54 minute(s), 40 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 1
                      Valeur(s) du Registre infectée(s): 9
                      Elément(s) de données du Registre infecté(s): 2
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 2

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc10tj0ecev (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc10tj0ecev (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\inrhc50tj0ecev (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\backupwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\General\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      C:\Windows\System32\lphc10tj0ecev.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\Windows\System32\phc10tj0ecev.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      0
                      1. Contributeur sécurité
                        Tu as encore des bébêtes qui traînent...

                        Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                        Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre-le sur ton Bureau à partir de ce lien :

                        http://www.commentcamarche.net/telecharger/telechargement 34055379 malwarebyte s anti malware

                        A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                        Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                        Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                        Redémarre ton ordinateur en mode sans échec

                        Relance MBAM grâce au raccourci présent sur ton bureau.

                        Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                        MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                        A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                        Si des malwares ont été détectés, leur liste s'affiche.
                        En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                        MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                        Ferme MBAM en cliquant sur Quitter.

                        Poste le rapport dans ta réponse

                        0
                        1. SmitFraudFix v2.353

                          Scan done at 11:01:40,15, 21/09/2008
                          Run from C:\SmitfraudFix
                          OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                          The filesystem type is NTFS
                          Fix run in safe mode

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                          !!!Attention, following keys are not inevitably infected!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          127.0.0.1 localhost
                          ::1 localhost

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                          S!Ri's WS2Fix: LSP not Found.

                          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                          GenericRenosFix by S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{CF0C3717-B005-4771-A1C1-08011CA25074}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{CF0C3717-B005-4771-A1C1-08011CA25074}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{CF0C3717-B005-4771-A1C1-08011CA25074}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, following keys are not inevitably infected!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                          »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                          Registry Cleaning done.

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                          !!!Attention, following keys are not inevitably infected!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» End

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 11:10:13, on 21/09/2008
                          Platform: Windows Vista SP1 (WinNT 6.00.1905)
                          MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                          C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                          C:\Program Files\Picasa2\PicasaMediaDetector.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                          C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                          C:\Program Files\itune\iTunesHelper.exe
                          C:\Windows\System32\lphc10tj0ecev.exe
                          C:\Windows\System32\rundll32.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                          C:\Windows\System32\rundll32.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\Neuf\Media Center\MediaCenter.exe
                          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                          C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Users\Fabrizio\Desktop\HiJackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                          O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                          O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                          O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                          O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\itune\iTunesHelper.exe"
                          O4 - HKLM\..\Run: [lphc10tj0ecev] C:\Windows\system32\lphc10tj0ecev.exe
                          O4 - HKLM\..\Run: [inrhc50tj0ecev] C:\Users\Fabrizio\AppData\Local\Temp\.ttD9DE.tmp.exe /CR=22C562C66C6D4EDAA2F792D1DF131E49C47315FBE92E51455A0528335A1EFD203FEF7348D77C74789A0005DE05E24FE3B8026577F7D4E8BC5C4FE3201421BEBE25B38302C02A6B3A62A6A9D4B15BBD558B
                          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\Neuf\Media Center\MediaCenter.exe"
                          O4 - HKCU\..\Run: [lphc10tj0ecev] C:\Windows\system32\lphc10tj0ecev.exe
                          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                          O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                          O13 - Gopher Prefix:
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                          O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                          O23 - Service: FreezeScreenSaver - Unknown owner - C:\Windows\system32\FreezeScreenSaver.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                          O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                          0
                          1. Contributeur sécurité
                            Redémarre l'ordinateur en mode sans échec .

                            Comment aller en Mode sans échec
                            1) Redémarre ton ordi
                            2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                            3) Tu verras un écran avec options de démarrage apparaître
                            4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                            5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                            ( ps : n'oublie pas, en mode sans échec, pas de connexion ! Donc copie ou imprime bien les info ci-dessous ...)

                            *Double click sur SmitfraudFix.exe

                            * Sélectionne 2 et presse "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

                            * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

                            ( Le correctif déterminera si le fichier wininet.dll est infecté.)

                            * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
                            pour remplacer le fichier corrompu.

                            * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

                            Le rapport se trouve à la racine de C\:
                            (dans le fichier "rapport.txt")

                            Poste ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport hijackthis ( fais en mode normal )
                            0
                            1. Voilà
                              Tu me dis quand je dois réactiver antivirus et compagnie ?

                              SmitFraudFix v2.353

                              Scan done at 10:37:52,35, 21/09/2008
                              Run from C:\SmitfraudFix
                              OS: Microsoft Windows [version 6.0.6001] - Windows_NT
                              The filesystem type is NTFS
                              Fix run in normal mode

                              »»»»»»»»»»»»»»»»»»»»»»»» Process

                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\SLsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\Windows\System32\spoolsv.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\Windows\system32\FreezeScreenSaver.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\SearchIndexer.exe
                              C:\Program Files\Windows Defender\MSASCui.exe
                              C:\Windows\system32\SearchProtocolHost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Windows Media Player\wmpnetwk.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                              C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                              C:\Program Files\Picasa2\PicasaMediaDetector.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                              C:\Program Files\itune\iTunesHelper.exe
                              C:\Windows\System32\lphc10tj0ecev.exe
                              C:\Windows\System32\rundll32.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\Neuf\Media Center\MediaCenter.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Windows\System32\rundll32.exe
                              C:\Windows\ehome\ehmsas.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\Program Files\Windows Live\Messenger\usnsvc.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Windows\System32\wsqmcons.exe
                              C:\Windows\system32\conime.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\SmitfraudFix\Policies.exe
                              C:\Windows\system32\cmd.exe
                              C:\Windows\system32\wbem\wmiprvse.exe

                              »»»»»»»»»»»»»»»»»»»»»»»» hosts

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fabrizio

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fabrizio\Application Data

                              »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Fabrizio\FAVORI~1

                              »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                              »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                              »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                              »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                              !!!Attention, following keys are not inevitably infected!!!

                              o4Patch
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                              !!!Attention, following keys are not inevitably infected!!!

                              IEDFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                              !!!Attention, following keys are not inevitably infected!!!

                              VACFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                              !!!Attention, following keys are not inevitably infected!!!

                              404Fix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                              !!!Attention, following keys are not inevitably infected!!!

                              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                              !!!Attention, following keys are not inevitably infected!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                              !!!Attention, following keys are not inevitably infected!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              "AppInit_DLLs"=""
                              "LoadAppInit_DLLs"=dword:00000001

                              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                              !!!Attention, following keys are not inevitably infected!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              "Userinit"="C:\\Windows\\system32\\userinit.exe,"

                              »»»»»»»»»»»»»»»»»»»»»»»» RK

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{CF0C3717-B005-4771-A1C1-08011CA25074}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{CF0C3717-B005-4771-A1C1-08011CA25074}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS3\Services\Tcpip\..\{CF0C3717-B005-4771-A1C1-08011CA25074}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                              »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                              »»»»»»»»»»»»»»»»»»»»»»»» End
                              0
                              1. Contributeur sécurité
                                Désactive le contrôle des comptes utilisateurs
                                (tu le réactiveras après ta désinfection):

                                * Va dans démarrer puis panneau de configuration
                                * Double Clique sur l'icône "Comptes d'utilisateurs"
                                * Clique ensuite sur désactiver et valide.

                                Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
                                http://siri.urz.free.fr/Fix/SmitfraudFix.exe

                                Déconnecte-toi, ferme toute tes applications et désactive tes défenses ( anti-virus, anti-spyware,...) le temps de la manip !!

                                Installe le soft à la racine de C:\ ( et pas ailleurs! --->"C\:SmitfraudFix.exe" ) .

                                Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

                                Utilisation ---> option 1 / Recherche :
                                Double clique sur l'icône "Smitfraudfix.exe" et sélectionne 1 (et pas sur autre chose sans notre accord !) pour créer un rapport des fichiers responsables de l'infection.

                                Poste le rapport ( "rapport.txt" qui se trouve sous C\: ) et attends la suite .

                                (Attention : process.exe est détecté par certains antivirus comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.)
                                0
                                1. Bonjour,

                                  Merci pour ton aide,çà me rassure un peu...

                                  Voilà le rapport, je pense avoir fait les bonnes manip

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 10:11:43, on 21/09/2008
                                  Platform: Windows Vista SP1 (WinNT 6.00.1905)
                                  MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                                  C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                                  C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                  C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                                  C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                  C:\Program Files\itune\iTunesHelper.exe
                                  C:\Windows\System32\lphc10tj0ecev.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\Neuf\Media Center\MediaCenter.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                                  C:\Program Files\Neuf\Media Center\httpd\httpd.exe
                                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                                  C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Windows\System32\wsqmcons.exe
                                  C:\Users\Fabrizio\Desktop\HiJackThis.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://format.packardbell.com/cgi-bin/redirect/?country=FR&range=AD&phase=8&key=IESTART
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                                  O4 - HKLM\..\Run: [MSPService] C:\Program Files\CyberLink\MagicSports\Kernel\MagicSports\MSPMirage.exe
                                  O4 - HKLM\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                                  O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\itune\iTunesHelper.exe"
                                  O4 - HKLM\..\Run: [lphc10tj0ecev] C:\Windows\system32\lphc10tj0ecev.exe
                                  O4 - HKLM\..\Run: [inrhc50tj0ecev] C:\Users\Fabrizio\AppData\Local\Temp\.ttD9DE.tmp.exe /CR=22C562C66C6D4EDAA2F792D1DF131E49C47315FBE92E51455A0528335A1EFD203FEF7348D77C74789A0005DE05E24FE3B8026577F7D4E8BC5C4FE3201421BEBE25B38302C02A6B3A62A6A9D4B15BBD558B
                                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                  O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\Neuf\Media Center\MediaCenter.exe"
                                  O4 - HKCU\..\Run: [lphc10tj0ecev] C:\Windows\system32\lphc10tj0ecev.exe
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
                                  O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                  O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                  O13 - Gopher Prefix:
                                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                  O23 - Service: FreezeScreenSaver - Unknown owner - C:\Windows\system32\FreezeScreenSaver.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                                  O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                  O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                  O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                                  O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                  0
                                  1. Contributeur sécurité
                                    Bonjour

                                    Avant de songer à démonter quoique ce soit,

                                    Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien

                                    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

                                    Enregistre HJTInstall.exe sur ton bureau.

                                    Double-clique sur HJTInstall.exe pour lancer le programme

                                    Tuto : https://www.malekal.com/tutoriel-hijackthis/
                                    http://pageperso.aol.fr/balltrap34/Hijenr.gif

                                    Accepte la license en cliquant sur le bouton "I Accept"
                                    Choisis l'option "Do a system scan and save a log file"
                                    Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                                    Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

                                    Colle le rapport que tu viens de copier sur ce forum
                                    0
                                    1. je suis sur un pc portable, donc pas moyen.
                                      J'ai jeté un coup d'oueil sur le forum, et apparamment d'autre on le même pb que moi.
                                      0
                                      1. le système lorsqu'il est attaqué ne peut plus faire grand chose.

                                        je te conseille de démonter votre disque dur et de le monter comme DD esclave dans un autre PC equipé d'un Antivirus puissant (Kaspersky de préférence) et à jour surtout, puis lancer l'analyse de votre disque dur sur ce PC.

                                        Espérant que ca marche.

                                        @tt
                                        0